Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Mindbody is a United States based booking and business management platform for wellness, fitness, salon and spa businesses. Its booking widget is embedded on a business website so that clients can schedule classes and appointments, and in doing so it collects client personal data such as name, contact details and the specific service booked. Because a booking can reveal a gym, physiotherapy or spa appointment, it may expose health or wellness related information that is special category data under Article 9 GDPR. The widget sets a session cookie for the booking and analytics cookies, and it processes data in the United States, so it must load only after the visitor has given consent.
Mindbody is a booking and business management platform based in the United States, built for wellness, fitness, salon and spa businesses. It lets a business publish a booking widget on its own website so that clients can browse classes and services, choose a time and pay for an appointment without leaving the page. The widget loads its code from Mindbody servers and renders a booking iframe inside the host page.
When a client makes a booking, Mindbody collects personal data such as the client name, contact details, telephone number and payment details, along with the specific class or service that was booked. Because that service can identify a gym, physiotherapy, salon or spa appointment, the booking can reveal health or wellness related information about the client. To run the booking flow, Mindbody sets a session cookie that holds the current booking, and it uses analytics cookies to measure how the widget is used. It can also recognise a returning client so their bookings are attributed to a single profile.
The booking details that Mindbody processes are personal data under the GDPR, and where a booking reveals health or wellness information it becomes special category data under Article 9 GDPR, which attracts a higher level of protection. Storing and reading the session and analytics cookies on the client device also falls within Article 5(3) of the ePrivacy Directive, which the CNIL in France, the German authorities under the TDDDG and the AEPD in Spain all enforce as a strict prior consent obligation for non essential cookies.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Consent is required before the non essential Mindbody cookies are set, because the analytics cookies and the recognition of returning clients are not strictly necessary to deliver the page. That consent must be freely given, specific, informed and unambiguous, and it must be as easy to refuse as to accept. Where the booking concerns a health or wellness service, the client special category data may only be processed on the basis of explicit consent under Article 9(2)(a) GDPR, which is a higher standard than ordinary consent and must be clearly separated and recorded.
Mindbody processes booking data on United States infrastructure, so European client data is transferred outside the European Economic Area. Such transfers require the EU Standard Contractual Clauses within the Mindbody Data Processing Addendum and a documented Transfer Impact Assessment that considers United States surveillance law, in line with the Schrems II ruling and the guidance of the European Data Protection Board. Where the data is special category health data, the sensitivity of the transfer is greater and the safeguards should be reviewed accordingly.
Gate the non essential Mindbody cookies behind your consent management platform so that analytics fire only after the relevant category is accepted, and request explicit consent before processing any health related booking. Describe Mindbody in your cookie policy, including the session and analytics cookies it sets and their lifetime. Sign the Mindbody Data Processing Addendum, complete a Transfer Impact Assessment and apply the shortest workable retention on client records. Collect only the data needed to complete the appointment and avoid capturing more detail about the service than is necessary.
Websites using Mindbody must obtain user consent under GDPR regulations.
DPIA considerations
A Data Protection Impact Assessment is strongly advised for the Mindbody booking widget, and the possible processing of special category health data under Article 9 GDPR makes it more likely that a DPIA is mandatory. Document the client personal data collected during booking, the fact that the service booked can reveal health or wellness information, the session and analytics cookies set on the visitor device, the transfer of data to the United States and the retention period applied to client records. Configure the widget so that it loads only after consent, obtain explicit consent where the booking is health related, and collect the minimum data needed to complete the appointment.
Sample consent text
We use Mindbody, a booking and business management service operated by Mindbody Inc. (United States), to let you schedule classes and appointments. Mindbody collects the details you enter and the service you book, sets cookies for the booking session and analytics, and may transfer this data to the United States under the EU Standard Contractual Clauses. Where your booking concerns a health or wellness service, we ask for your explicit consent. Mindbody will only load if you click Accept.
Third-party domains contacted
mindbodyonline.comwidgets.mindbodyonline.combrandedweb.mindbodyonline.comapi.mindbodyonline.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| ASP.NET_SessionId | HTTP cookie (first party) | Session | Maintains the booking session within the Mindbody widget so that class or appointment selections, cart contents and sign in state persist during a single visit. Set by the Mindbody application that serves the booking iframe. |
| _ga | HTTP cookie (analytics) | 2 years | Google Analytics cookie set on the Mindbody domain to distinguish individual visitors and measure how the booking widget is used. |
| _gid | HTTP cookie (analytics) | 24 hours | Google Analytics cookie set on the Mindbody domain to distinguish visitors over a short period and aggregate booking widget usage statistics. |
| _gat | HTTP cookie (analytics) | 1 minute | Google Analytics cookie used to throttle the rate of requests to the analytics servers while the Mindbody booking widget is loaded. |
Mindbody uses cookies for user preferences — inform visitors with a consent banner.
The Mindbody booking widget sets a session cookie that holds your current booking while you choose a class or appointment, and analytics cookies that measure how the widget is used. Mindbody can also recognise a returning client so bookings are linked to a single profile. The analytics cookies are not strictly necessary and require consent.
Yes. The Mindbody widget writes non essential analytics cookies and can process client data, so under the ePrivacy rules you must obtain prior consent before those cookies are set. Where a booking reveals health or wellness information, you also need explicit consent for that special category data. Only the strictly necessary booking session may run before consent.
The legal basis for the non essential cookies is consent under Article 6(1)(a) GDPR, combined with the prior consent requirement of Article 5(3) of the ePrivacy Directive. Where a booking reveals health or wellness information, the special category data may only be processed on the basis of explicit consent under Article 9(2)(a) GDPR. Legitimate interest is not available for this processing.
Yes. Mindbody hosts its platform on United States infrastructure, so European client booking data is transferred there. You need the EU Standard Contractual Clauses in the Mindbody Data Processing Addendum and a Transfer Impact Assessment. Where the booking data is special category health data, review the safeguards for that heightened sensitivity.
A Data Protection Impact Assessment is strongly recommended, and because a booking can involve special category health data under Article 9 GDPR, a DPIA is more likely to be mandatory. Assess the client data collected, the possible health information revealed by the service booked, the cookies set on the device and the United States transfer.
Load the non essential Mindbody cookies only through your consent management platform after the relevant category is accepted, and request explicit consent before any health related booking. Describe Mindbody in your cookie policy, sign the Data Processing Addendum, complete a Transfer Impact Assessment and apply a short retention period. Collect only the data needed to complete the appointment.
Alternatives include Vagaro, Booksy, Fresha, Acuity Scheduling and Glofox. They raise similar consent, cookie and transfer questions, and several also involve wellness bookings that can reveal health information, so check their hosting location and data processing terms before assuming any is lighter on privacy.
Add a dedicated entry that names Mindbody as the provider, lists the booking session and analytics cookies with their lifetimes, explains that a booking can reveal health or wellness information, and discloses the United States transfer and its safeguard. Keep the entry in step with your consent categories and your explicit consent flow for health related bookings.